{"id":23116,"date":"2026-09-16T06:40:15","date_gmt":"2026-09-16T06:40:15","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=23116"},"modified":"2026-09-16T06:40:16","modified_gmt":"2026-09-16T06:40:16","slug":"sentinelone-integration","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/","title":{"rendered":"ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Speed and clarity are the ultimate advantages for modern SOC teams. The integration of<a href=\"https:\/\/any.run\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <\/a><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN<\/strong><\/a> into<a href=\"https:\/\/www.sentinelone.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <strong>SentinelOne<\/strong><\/a> delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into actionable insights without leaving the platform.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About the ANY.RUN &amp; SentinelOne Integration <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The integration between ANY.RUN and SentinelOne brings advanced malware analysis and global threat intelligence into the platform as native, actionable data.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of manually exporting files or switching between multiple consoles, security teams can operationalize ANY.RUN\u2019s capabilities within the SentinelOne ecosystem.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>New Connectors for<\/strong><a href=\"https:\/\/any.run\/features\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong> <\/strong><\/a><a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Interactive Sandbox<\/strong><\/a><strong> and<\/strong><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong> <\/strong><\/a><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Lookup<\/strong><\/a><strong> (via Singularity Hyperautomation): <\/strong> <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Accelerate File\/URL Triage with Automated Behavioral Analysis:<\/strong> Automatically submit suspicious files and URLs from alerts to the ANY.RUN sandbox. Behavioral verdicts and risk scores are delivered directly into SentinelOne, enabling evidence-based decisions.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Enrich Alert Investigations with Instant Context:<\/strong> Perform on-demand lookups for IOCs like hashes, IPs, and domains. This provides analysts with immediate data on industry targeting, malware families, and related infrastructure without leaving the alert interface.  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Existing Integration for<\/strong><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong> <\/strong><\/a><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a><strong> (via the native TAXII Connect IOC Ingestion app on the SentinelOne Marketplace)<\/strong> <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Strengthen Proactive Defense with High-Fidelity Indicators:<\/strong> Stream verified malicious indicators (IPs, domains, URLs) directly into the platform via STIX\/TAXII. This allows for automated correlation against endpoint logs and the generation of native alerts for matching threats.  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By turning malware analysis and threat enrichment into a native part of the investigation pipeline, ANY.RUN and SentinelOne empower SOC teams to stay ahead of evasive attacks while maximizing the value of their existing security stack.  <\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Streamline triage and cut response time inside your SentinelOne environment.\n<\/span> \n<br>\nSlash MTTR. Eliminate console switching. Reduce exposure.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=sentinelone-integration&#038;utm_term=160926&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nIntegrate ANY.RUN<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\"> 1. ANY.RUN Interactive Sandbox: Improve Triage Speed and Detect Evasive Attacks <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This integration component can be used via<a href=\"https:\/\/www.sentinelone.com\/platform\/singularity-hyperautomation\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <strong>Singularity Hyperautomation<\/strong><\/a>, allowing for deep behavioral analysis of suspicious artifacts.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When SentinelOne triggers an alert, it<strong> automatically sends the file or URL to the <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN Sandbox<\/a> <\/strong>based on your pre-set preferences (like OS or analysis duration). Once the analysis is complete, behavioral verdicts (malicious, suspicious, or benign) are delivered directly into the <strong>Notes<\/strong> section of the specific SentinelOne alert.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Benefits:<\/strong>  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Faster Time-to-Verdict:<\/strong> By automating the submission process, analysts receive a definitive verdict in minutes, significantly reducing <strong>MTTR<\/strong> (Mean Time to Resolution).  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reduced Manual Routine:<\/strong> Eliminates the need for analysts to manually export files or copy-paste URLs into external tools, preventing &#8220;console fatigue&#8221;.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Standardized Triage:<\/strong> Templates ensure that every suspicious artifact is analyzed using the same rigorous methodology, regardless of the analyst&#8217;s experience level.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Higher Detection of Evasive Threats:<\/strong> Behavioral analysis catches advanced threats that often bypass the static detection layers of an EDR.  <\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Practical Use Case: Automated Malware Triage <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When an alert triggers due to a suspicious file execution, the Hyperautomation workflow automatically or manually sends the file itself to the ANY.RUN Sandbox. The analyst immediately sees a &#8220;Malicious&#8221; verdict in the alert Notes, allowing them to initiate containment actions without ever leaving the SentinelOne console.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. ANY.RUN Threat Intelligence Lookup: Identify and Prioritize Risks Faster <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <\/a><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Lookup<\/strong><\/a> component, available via Singularity Hyperautomation, provides <strong>on-demand enrichment of indicators<\/strong> using ANY.RUN\u2019s vast database of millions of previous sandbox investigations across 16,000 organizations and 700,000 analysts.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The moment a suspicious file hash, IP, or domain appears, the system scans ANY.RUN&#8217;s threat intelligence history. Analysts can also <strong>force a manual check<\/strong> at any point during active hunting. The resulting intelligence, including <strong>threat tags, industry targeting info, and &#8220;last seen&#8221; data<\/strong>, is seamlessly added <strong>directly into the SentinelOne alert&#8217;s Notes<\/strong>.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Benefits:<\/strong>  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Smarter Prioritization:<\/strong> Immediate access to industry targeting data helps SOC managers quickly identify if they are facing a serious incident.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fewer Tier 2 Escalations:<\/strong> Tier 1 analysts gain enough context to <strong>confidently close false positives<\/strong> or <strong>resolve actual threats <\/strong>on their own, reducing bottlenecks.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Enhanced Decision Accuracy:<\/strong> Access to historical behavioral data from over 700,000 analysts worldwide <strong>reduces the risk of incorrect alert closures<\/strong>.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Improved Quality of Evidence:<\/strong> Escalated cases include a <strong>full TI context<\/strong>, allowing senior investigators to start their work with a complete picture of the threat.  <\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Practical Use Case: IOC Enrichment during Investigation <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When a Singularity alert flags a suspicious file execution, the system can instantly run a TI Lookup enrichment for the specific file hash.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"439\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-1024x439.png\" alt=\"\" class=\"wp-image-23118\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-1024x439.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-300x129.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-768x329.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-1536x659.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-370x159.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-270x116.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1-740x317.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/image1.png 1873w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>TI Lookup provides alert context in seconds<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Within seconds, a note pops up in the console revealing that the hash matches a <strong>known ransomware strain previously analyzed in ANY.RUN\u2019s Sandbox<\/strong>. Instead of wasting time on manual research, the analyst immediately gets the full threat profile, allowing them to quarantine the host right away without ever leaving the console.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\"> 3. ANY.RUN Threat Intelligence Feeds: Upgrade Defense Against Emerging Threats <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <\/a><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Feeds<\/strong><\/a> integration utilizes the<strong> native TAXII Connect IOC Ingestion app<\/strong> found in the <strong>SentinelOne Marketplace <\/strong>to systematically fortify your environment.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This component establishes a <strong>continuous, live stream of verified malicious IPs, domains, and URLs from ANY.RUN<\/strong> directly into your perimeter. The indicators are extracted and delivered in real time from the newest sandbox investigations of emerging malware &amp; phishing threats across 16,000 organizations and 700,000 analysts around the world.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Utilizing the standardized <strong>built-in STIX\/TAXII mechanism<\/strong>, it completely eliminates the need for custom scripts or maintenance overhead. The system silently cross-references endpoint traffic against these fresh indicators, <strong>automatically triggering native high-priority matches<\/strong> the second an internal asset interacts with a blacklisted entity.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Benefits:<\/strong>  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Proactive Threat Detection:<\/strong> Fresh indicators are added to the system as soon as they appear in live sandbox investigations, improving MTTD (Mean Time to Detection).  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Elimination of Blind Spots:<\/strong> Provides access to <strong>99% unique malicious infrastructure<\/strong> that traditional, slower-moving feeds often miss.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Reduced Tier 1 Workload:<\/strong> Because indicators are pre-verified as malicious, the resulting alerts are <strong>high-fidelity<\/strong>, leading to fewer false positives to investigate.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Scalable Operational TI:<\/strong> The integration scales across multiple sites and configurations, making it <strong>ideal for large <\/strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktoenterprise\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Enterprises<\/strong><\/a><strong> and <\/strong><a href=\"https:\/\/any.run\/mssp\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktomssplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>MSSPs<\/strong><\/a>.  <\/li>\n<\/ul>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\n<span class=\"highlight\">Integrate fresh Threat Intelligence to identify attacks early.<\/span> \n<br>\nEliminate blind spots and upgrade overall SOC ROI.\n<\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nIntegrate ANY.RUN<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h3 class=\"wp-block-heading\">Practical Use Case: Detecting Emerging Campaigns <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When a fresh phishing campaign targeting your sector is active globally, its malicious infrastructure is <strong>streamed to SentinelOne in real-time<\/strong>. If an employee clicks an obfuscated link from that specific campaign minutes later, SentinelOne\u2019s native detection engine identifies the match against the ingested indicators, instantly blocking the connection and flagging a critical alert. This protection happens automatically at the platform level, stopping advanced attacks based on fresh global telemetry.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Integrate ANY.RUN with SentinelOne Singularity <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The integration is designed for rapid deployment, utilizing native SentinelOne modules to ensure that setup does not require custom scripts or complex development. Depending on the product you are connecting, there are two primary paths for integration.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hyperautomation) 1. Integrating Sandbox &amp; TI Lookup (via Singularity Hyperautomation) <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Sandbox and TI Lookup components are implemented through<a href=\"https:\/\/www.sentinelone.com\/platform\/singularity-hyperautomation\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <strong>Singularity Hyperautomation<\/strong><\/a>.  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 1: Connect the ANY.RUN Integration<\/strong>  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Navigate to the <strong>Hyperautomation<\/strong> section in your SentinelOne console. Open the <strong>Integrations<\/strong> tab, locate <strong>ANY.RUN<\/strong>, and click &#8220;Connect.&#8221; You will need to provide your <strong>ANY.RUN API key<\/strong> to establish the link.  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 2: Install Workflow Templates<\/strong>  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Go to the <strong>Templates<\/strong> section within Hyperautomation and search for ANY.RUN. Select and install the templates that fit your SOC needs, such as:  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>TI Lookup workflow<\/strong> for indicator enrichment.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Sandbox URL workflow<\/strong> for automated URL analysis.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Sandbox file workflow<\/strong> for automated file analysis.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 3: Configure Automation Criteria<\/strong>  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Set the specific rules for when these workflows should trigger (e.g., based on <strong>alert severity<\/strong>, name, or type).  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 4: Define Analysis Parameters<\/strong>  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For Sandbox templates, specify the OS and environment version for the analysis. For TI Lookup, define which alert indicators (hash, IP, or URL) should be checked. Note that you will also need to create a password for the workflow as a technical requirement of the platform.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Note:<\/em><\/strong><em> Singularity Hyperautomation is an independently licensed module within the SentinelOne platform.<\/em>  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SentinelOne Marketplace) 2. Integrating TI Feeds (via SentinelOne Marketplace) <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The TI Feeds connector uses the native <strong>TAXII Connect IOC Ingestion<\/strong> app to stream verified indicators directly into your detection logic.  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 1: Install the Connector<\/strong>  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Open the<a href=\"https:\/\/www.sentinelone.com\/partners\/singularity-marketplace\/\" target=\"_blank\" rel=\"noreferrer noopener\"> <strong>SentinelOne Singularity Marketplace<\/strong><\/a>, find the <strong>TAXII Connect IOC Ingestion<\/strong> integration, and install it.  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 2: Create the Configuration <\/strong> <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Within the app, create a new configuration and provide the following details:  <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Name and Scope:<\/strong> Define the configuration&#8217;s identity within your environment.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Endpoint URL:<\/strong> Enter the TAXII URL for your desired ANY.RUN TI Feeds collection (e.g., &#8220;All Indicators,&#8221; &#8220;IPs,&#8221; &#8220;Domains,&#8221; or &#8220;URLs&#8221;).  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Credentials:<\/strong> Provide the <strong>username and password<\/strong> associated with your ANY.RUN TI Feeds subscription.  <\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Step 3: Operationalization<\/strong>  <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Once connected, indicators will automatically stream into the system. If an ingested indicator matches an event on an endpoint, SentinelOne will generate a native <strong>&#8220;Threat Intelligence Indicator Match&#8221;<\/strong> alert in the console.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Trusted by 700,000+ cybersecurity professionals and 16,000+ organizations across critical industries, including <a href=\"https:\/\/any.run\/cybersecurity-blog\/fortune-500-enterprise-success-story\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>64% of Fortune 500<\/strong><\/a> companies, <a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN<\/strong> <\/a>helps security teams detect and investigate threats faster. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our <a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Interactive Sandbox<\/strong><\/a> provides real-time behavioral analysis of suspicious files and URLs, enabling confident triage and response. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Lookup<\/strong><\/a> and <a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=sentinelone-integration&amp;utm_term=160926&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Threat Intelligence Feeds<\/strong><\/a> deliver live, verified threat data that strengthens detection and improves prioritization. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By embedding analysis and intelligence into daily SOC workflows, ANY.RUN helps organizations reduce response time, lower operational costs, and minimize security risk.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Speed and clarity are the ultimate advantages for modern SOC teams. The integration of ANY.RUN into SentinelOne delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work. Let\u2019s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":23127,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[81],"tags":[57,10],"class_list":["post-23116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-integrations-connectors","tag-anyrun","tag-cybersecurity"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ANY.RUN &amp; SentinelOne: One Workspace, Instant Threat Context<\/title>\n<meta name=\"description\" content=\"Eliminate context switching, accelerate incident response, and drive higher ROI by integrating ANY.RUN in your SentinelOne workflows.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ANY.RUN\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/\"},\"author\":{\"name\":\"ANY.RUN\",\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"headline\":\"ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response\",\"datePublished\":\"2026-09-16T06:40:15+00:00\",\"dateModified\":\"2026-09-16T06:40:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/\"},\"wordCount\":1574,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/sentinelone_blog-scaled.png\",\"keywords\":[\"ANYRUN\",\"cybersecurity\"],\"articleSection\":[\"Integrations &amp; connectors\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/\",\"name\":\"ANY.RUN & SentinelOne: One Workspace, Instant Threat Context\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/sentinelone_blog-scaled.png\",\"datePublished\":\"2026-09-16T06:40:15+00:00\",\"dateModified\":\"2026-09-16T06:40:16+00:00\",\"description\":\"Eliminate context switching, accelerate incident response, and drive higher ROI by integrating ANY.RUN in your SentinelOne workflows.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#primaryimage\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/sentinelone_blog-scaled.png\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/sentinelone_blog-scaled.png\",\"width\":2560,\"height\":1243,\"caption\":\"SentinelOne sandbox\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/sentinelone-integration\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Integrations &amp; connectors\",\"item\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/category\\\/integrations-connectors\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/any.run\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\\\/\\\/any.run\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\\\/\\\/any.run\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/www.any.run\\\/\",\"https:\\\/\\\/x.com\\\/anyrun_app\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/30692044\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/any.run\\\/\",\"name\":\"ANY.RUN\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g\",\"caption\":\"ANY.RUN\"},\"url\":\"https:\\\/\\\/any.run\\\/cybersecurity-blog\\\/author\\\/a-bespalova\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ANY.RUN & SentinelOne: One Workspace, Instant Threat Context","description":"Eliminate context switching, accelerate incident response, and drive higher ROI by integrating ANY.RUN in your SentinelOne workflows.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/","twitter_misc":{"Written by":"ANY.RUN","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/"},"author":{"name":"ANY.RUN","@id":"https:\/\/any.run\/"},"headline":"ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response","datePublished":"2026-09-16T06:40:15+00:00","dateModified":"2026-09-16T06:40:16+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/"},"wordCount":1574,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/sentinelone_blog-scaled.png","keywords":["ANYRUN","cybersecurity"],"articleSection":["Integrations &amp; connectors"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/","url":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/","name":"ANY.RUN & SentinelOne: One Workspace, Instant Threat Context","isPartOf":{"@id":"https:\/\/any.run\/"},"primaryImageOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#primaryimage"},"image":{"@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#primaryimage"},"thumbnailUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/sentinelone_blog-scaled.png","datePublished":"2026-09-16T06:40:15+00:00","dateModified":"2026-09-16T06:40:16+00:00","description":"Eliminate context switching, accelerate incident response, and drive higher ROI by integrating ANY.RUN in your SentinelOne workflows.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#primaryimage","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/sentinelone_blog-scaled.png","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/09\/sentinelone_blog-scaled.png","width":2560,"height":1243,"caption":"SentinelOne sandbox"},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/sentinelone-integration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Integrations &amp; connectors","item":"https:\/\/any.run\/cybersecurity-blog\/category\/integrations-connectors\/"},{"@type":"ListItem","position":3,"name":"ANY.RUN &amp; SentinelOne: One Workspace, Instant Context for Rapid Response"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/x.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"ANY.RUN","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a921d1fbcf45a0476667c89b7999bc2bb3c028b518acc569da69c8797e53a84?s=96&d=mm&r=g","caption":"ANY.RUN"},"url":"https:\/\/any.run\/cybersecurity-blog\/author\/a-bespalova\/"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=23116"}],"version-history":[{"count":12,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23116\/revisions"}],"predecessor-version":[{"id":23132,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/23116\/revisions\/23132"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/23127"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=23116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=23116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=23116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}